Privacy at TapDone
Effective July 21, 2026
TapDone turns spare phones into wall-mounted Done buttons for household tasks. This page explains what data the TapDone apps and this website handle, where it goes, and what never leaves your home. "TapDone", "we" and "us" mean the team behind the app; you can always reach us at hello@tapdone.now.
The short version
- Live face recognition happens entirely on your devices. Camera frames are processed in memory and discarded — nothing is recorded, streamed or uploaded.
- Face enrollment captures are end-to-end encrypted. They sync between your household's devices only in sealed form; the key never leaves your devices, so our servers store data they cannot read.
- Household data syncs through our servers — tasks, who tapped what and when, member names — so all your Buttons show the same board. It's encrypted in transit, but it is not end-to-end encrypted.
- No ads, no data sales, no analytics or tracking SDKs.
- You can delete face data — per person or all of it — and your whole household, any time.
1. What we collect, and why
Account
Only the person who sets up a household signs in, with an email address and password. We keep that email and an account identifier, and we email you verification and password-reset codes. Everyone else in the house joins with a pairing code or is simply a name on the board — no account, no email, no password.
Household data (synced)
To keep every Button and phone in a household showing the same board, these sync through our servers and are stored there:
- Tasks — names, schedules, points, icons, and who they're assigned to
- Completions — which task was done, when, by which member, how it was credited (face match, picked from a list, guest, or unattributed), and on which Button
- Household members — the first name or nickname you give them, and their role
- Devices — the name you give each Button (like "Hallway") and basic health such as battery level
- Rewards and redemptions, if you use points
This data is encrypted in transit (TLS) and stored on our servers in readable form so sync can work. It is not end-to-end encrypted.
Face match (optional)
Face match exists to answer one question — who is standing at the Button — and it is off until a household adult turns it on. Every other feature works without it.
- Recognition runs on the device. The camera reads frames in memory, the match is computed locally, and the frames are discarded. No video or photo is recorded, and nothing from the live camera is ever uploaded.
- Enrollment captures are sealed before they're stored. When you enroll a face, the captures are encrypted on the device with a key belonging to your household (AES-256-GCM). That key lives in the device's secure keychain and is handed to other devices only directly, device-to-device, during pairing. It is never uploaded.
- Our servers only ever hold the sealed version. If your household syncs across devices, the encrypted captures pass through and rest on our servers as ciphertext we cannot open.
- Deleting is built in. You can delete any one person's face data, or wipe all face data for the household in one action — both remove the server copies too. Removing a member from the household also deletes their face data.
Task photos
A photo attached to a task stays on the device where it was added. Task photos are never uploaded.
What we don't collect
The apps contain no analytics, advertising or crash-reporting SDKs. We don't collect location, contacts, or advertising identifiers, and this website sets no tracking cookies. If we ever add anonymous crash diagnostics to help us fix bugs, we'll update this policy first.
2. Where data lives
TapDone runs on Amazon Web Services in the United States: sign-in accounts, the sync database, and the email service that sends verification codes. AWS processes this data for us and doesn't use it for anything else. Your devices also keep a local copy of your household's board.
3. Sharing
We don't sell data, we don't show ads, and we don't share your data with third parties for their own use. The only parties that touch it are the cloud services above, acting on our instructions. We would disclose data if the law genuinely required it, and we'd tell you unless we're legally barred from doing so.
4. Retention and deletion
- Face data — delete per person or household-wide in settings, effective locally and on our servers.
- Members — removing someone deletes their face data; their name remains on past completions unless you delete those too.
- Household and account — email hello@tapdone.now and we'll delete your account and your household's server-side data. Task history otherwise lives for as long as your household does.
5. Children
TapDone is set up and controlled by adults. Kids don't need an account, a device or an email — a child in TapDone is typically just a first name on the board. If an adult enrolls a child's face, it's handled exactly as described above: recognized on-device, synced only in end-to-end encrypted form, deletable at any time. We never knowingly collect personal information directly from children.
6. Your choices and rights
Face match is optional. Depending on where you live you may have legal rights to access, correct, export or delete your personal data; email us and we'll honor them regardless of where you live.
7. Changes
When this policy changes, we'll update this page and the date at the top. If a change is material — new data collected, or a new party receiving it — we'll say so plainly on the site before it takes effect.
8. Contact
Questions, deletion requests, or anything unclear: hello@tapdone.now.